ΊΪΑΟΚΣΖ΅

Reference Check Authorization Form Template for Malaysia

Generate a bespoke document

What is a Reference Check Authorization Form?

The Reference Check Authorization Form is a crucial document in the Malaysian employment landscape, designed to facilitate the verification of potential employees' work history and credentials while ensuring compliance with local laws, particularly the Personal Data Protection Act 2010. This document becomes necessary during the hiring process when an organization needs to verify a candidate's employment history, performance, and qualifications with previous employers or reference providers. It serves as a legal safeguard for all parties involved by clearly defining the scope of information that can be shared and ensuring proper consent for data collection and processing. The form is structured to meet Malaysian regulatory requirements while providing flexibility for use across various industries and organization types.

Frequently Asked Questions

Is a Reference Check Authorization Form legally binding in Malaysia?

Yes, a properly executed Reference Check Authorization Form is legally binding in Malaysia under the Personal Data Protection Act 2010. Once signed, it creates a legal obligation for the applicant to provide accurate information and grants the employer legitimate consent to process personal data for reference verification purposes. The form must comply with PDPA 2010 requirements to be enforceable.

Can employers conduct reference checks without a signed authorization form in Malaysia?

No, employers cannot legally conduct reference checks without proper written consent under Malaysia's Personal Data Protection Act 2010. Collecting personal data without authorization can result in fines up to RM300,000 for individuals or RM500,000 for companies. The signed form serves as proof of consent for data processing activities.

How long does it take to prepare a Reference Check Authorization Form in Malaysia?

A standard Reference Check Authorization Form can be prepared in 15-30 minutes using a template. However, allow 1-2 business days for legal review if your organization requires compliance verification. The actual reference check process typically takes 3-5 working days once the signed form is received.

What are the PDPA 2010 requirements for reference check forms in Malaysia?

Under PDPA 2010, reference check forms must include a clear data processing notice, specify the purpose of data collection, identify data recipients, and obtain explicit consent. The form must also inform applicants of their rights to access and correct their personal data. Failure to comply can result in significant penalties under Malaysian law.

How is a Reference Check Authorization different from a Background Check Consent Form in Malaysia?

A Reference Check Authorization specifically covers employment history verification from previous employers, while a Background Check Consent Form covers broader screening including criminal records, credit checks, and educational verification. Reference checks focus on work performance and character, whereas background checks examine legal and financial history under different regulatory requirements.

What mistakes do Malaysian employers make with reference check authorization forms?

Common mistakes include failing to specify data retention periods as required by PDPA 2010, not providing clear opt-out mechanisms, using overly broad consent language, and neglecting to inform applicants about their data protection rights. Many employers also forget to securely store signed forms or fail to limit data sharing to legitimate business purposes only.

Can job applicants refuse to sign a reference check authorization form in Malaysia?

Yes, job applicants can legally refuse to sign a reference check authorization form in Malaysia, as consent under PDPA 2010 must be freely given. However, employers may choose not to proceed with the application if reference verification is a mandatory part of their hiring process. Applicants should be informed that refusal may affect their candidacy.

Reviewed by

Legal Engineer, GenieAI

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Legal Engineer, GenieAI

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Malaysia

Reviewed by

&

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Reference Check Authorization Form

A Reference Check Authorization Form is an essential legal document that grants prospective employers in Malaysia the explicit consent needed to verify your employment history, qualifications, and professional background with previous employers and reference providers. Under Malaysia's Personal Data Protection Act 2010, employers must obtain your written authorization before collecting, processing, or disclosing your personal information during the hiring process.

When do you need this document?

You'll need this form whenever you're applying for new employment opportunities in Malaysia and the prospective employer requires verification of your work history. This typically occurs during the final stages of the hiring process, after initial interviews but before a job offer is finalized. The form is particularly important for senior positions, roles requiring security clearance, or positions in regulated industries like banking, healthcare, or education. Many Malaysian companies now require this authorization as standard practice to ensure due diligence in their hiring processes and to protect themselves from potential liability issues.

Key legal considerations

The authorization must clearly specify what information can be shared and with whom, ensuring compliance with data protection principles. You should carefully review the scope of authorization to understand exactly what details about your employment history, performance ratings, salary information, and personal conduct may be disclosed. The form should include specific time limits for how long the authorization remains valid and must outline your rights regarding data access and correction. It's crucial that the document includes provisions for data security and confidentiality, ensuring that your personal information is handled appropriately throughout the reference checking process. Consider whether you want to limit certain types of information from being shared, such as salary details or performance reviews.

Legal requirements in Malaysia

Under the Personal Data Protection Act 2010, the form must obtain your explicit and informed consent before any personal data processing occurs. The Employment Act 1955 requires that reference checks be conducted fairly and without discrimination, while the Contracts Act 1950 ensures the authorization meets basic contract formation requirements. The document must clearly identify the data controller (prospective employer), specify the purpose of data collection, and outline your rights as a data subject, including the right to access and correct your information. Malaysian law also requires that the form includes details about data retention periods and the security measures in place to protect your personal information. The Industrial Relations Act 1967 provides additional protections against unfair labor practices, ensuring that reference checks cannot be used to discriminate against applicants based on protected characteristics.

GOVERNING LAW

Applicable law

This Reference Check Authorization Form is drafted to comply with Malaysia law. Key legislation includes:







Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it